Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSON document within a PUT /gallery/api/media request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Alteryx Server 跨站脚本漏洞
Vulnerability Description
Alteryx Server是Alteryx公司的一个云托管或自托管的应用程序。用于发布、共享和执行工作流。 Alteryx Server 2022.1.1.42590版本存在跨站脚本漏洞,该漏洞源于不对上传的文件进行类型验证,允许攻击者通过更改上传文件的扩展名来上传任意文件。
CVSS Information
N/A
Vulnerability Type
N/A